What happened
Salt Labs disclosed on 2026-10-01 that a single malicious email could hijack a Manus agent: the platform's guardrails detected the plaintext malicious instruction but were bypassed with JSFuck JavaScript obfuscation that was decoded and executed. The agent then established a reverse shell and located credentials/tokens for the user's connected services. Crucially, Manus' own security alert fired only after the code had already run — a detection-but-not-prevention failure unique to autonomous agents.
Why it matters
This is a working, real-world PoC of the agentic-attack class the broader digest tracks: indirect prompt injection reaching code execution and credential theft across connected services with zero victim interaction beyond a routine request. It demonstrates that prompt-injection guardrails are insufficient and that agentic platforms need runtime tool/API-action authorization (fail-closed). The disclosure also landed days before Manus 2.0 shipped email-triggered agent automations, which would let an email start an agent run with no human in the loop.
Attack vector
Adversary sends a malicious email to the victim's inbox; when the user asks Manus to check messages, the agent treats the email body as instructions (indirect prompt injection). Plaintext malicious instructions are blocked by guardrails, but an obfuscated JavaScript payload is decoded and executed to establish a reverse shell and harvest tokens for the user's connected third-party accounts. No password, link-click, or further victim action required.
Affected systems
Manus general-purpose agentic AI platform (flaw fixed; not currently exploitable)
Mitigation
Fixed via responsible disclosure through Meta's bug bounty; Manus is no longer exploitable for this chain. Operator guidance: treat all retrieved email/document/web content as untrusted input, separate content from instructions, and monitor agent tool/API actions rather than relying on prompt guardrails alone — especially given Manus 2.0's new email-triggered automations.